Hatch3r Dependency Drafter — Security agent for Claude Code
Dependency-analysis specialist who drafts version-bump and dependency-change proposals — assesses upgrade impact, security advisories, and breaking changes, then hands a reviewable proposal to a separ.
How to install Hatch3r Dependency Drafter
Installs to ~/.claude/agents/hatch3r-hatch3r-hatch3r-dependency-drafter.md
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/hatch3r/hatch3r/HEAD/agents/hatch3r-dependency-drafter.md -o ~/.claude/agents/hatch3r-hatch3r-hatch3r-dependency-drafter.md Restart Claude Code, or start a new session, for it to be picked up.
What Hatch3r Dependency Drafter does
id: hatch3r-dependency-drafter type: agent description: Dependency-analysis specialist who drafts version-bump and dependency-change proposals — assesses upgrade impact, security advisories, and breaking changes, then hands a reviewable proposal to a separate reviewer/applier. Drafts only; never installs, edits a manifest, or applies an upgrade. Use when planning a dependency upgrade, triaging a CVE advisory, or evaluating a new direct dependency. model: standard tags: [devops, maintenance]
Alternatives in Security
- Ark Security Patcher — Fix security vulnerabilities in Ark by researching CVEs, analyzing impact, proposing mitigations, implementing 419 ★
- Electron Ipc Engineer — Use this agent for any change that touches Electron IPC — adding/removing channels, modifying main.ts ↔ preloa 204 ★
- Advisory Hunter — Phase 1 intelligence gathering agent that collects security advisories (CVE, GHSA, OSV) with adaptive time exp 125 ★
Full documentation available on GitHub
View Source RepositoryRelated Agents
Vuln Discloser
Re-verifies confirmed findings against the latest upstream release and drafts maintainer-ready security adviso
Dependency Vetter
Supply-chain security audit of a third-party package (npm today) at ONE exact resolved version, run BEFORE it
Zp Report Drafter
ZeroProtocol report drafter. Use to turn one verified finding into a submission-ready draft for HackerOne, Bug
Dependency Doctor
Dependency health management — outdated packages, vulnerabilities (CVE), breaking change risk for major bumps.
Watchdog
Use as a parallel safety monitor during large refactors or multi-agent runs. Watches for security, breaking-ch
QA Release Ops
ADLC Agent 4 — integration/regression tests, eval suite, blocking security gate on stage:qa PRs; drafts the Ga
Related Skills
Hatch3r Migration Plan
Create a phased migration plan for a major dependency or framework upgrade. Analyzes breaking changes and prod
Memory Propose
Distill what this session learned about the repo into reviewable team-memory proposals (Reviewed Memory).
Pricing Analysis
Run a comprehensive pricing analysis — assesses current pricing, analyzes competition, estimates willingness-t